2

Third Party Risk Analyst Remote Jobs in California

Remote within the United States. Occasional travel for client engagements or firm offsites at ... Risk Analyst Contract Application." Applications are reviewed on a rolling basis.

Remote within the United States. Occasional travel for client engagements or firm offsites at ... Risk Analyst Contract Application." Applications are reviewed on a rolling basis.

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases

Crunchbase has a remote-first approach, and is open to hiring in residents of these states ... Own the enterprise vendor inventory and third-party risk management process, including approved use ...

next page

Showing results 1-20

Third Party Risk Analyst Remote information

What does a Third Party Risk Analyst do?

A Third Party Risk Analyst is responsible for assessing and managing the risks associated with an organization’s external vendors or partners. They evaluate third parties to ensure they meet security, compliance, and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and recommending risk mitigation strategies. Working remotely, these analysts use digital tools to collaborate with internal teams and communicate with vendors.

What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst (Remote), and why are they important?

To thrive as a Third Party Risk Analyst (Remote), you need a solid understanding of risk management frameworks, vendor due diligence, and compliance regulations, typically supported by a bachelor's degree in a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) platforms, and certifications such as CTPRA or CISA are often required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for evaluating and managing third-party risks collaboratively. These skills ensure organizations can identify, assess, and mitigate risks posed by external partners, maintaining regulatory compliance and protecting business interests.

How does a Third Party Risk Analyst collaborate with other departments in a remote work setting?

As a remote Third Party Risk Analyst, collaboration with departments such as procurement, legal, IT security, and compliance is typically achieved through regular virtual meetings and shared documentation platforms. You’ll often coordinate with these teams to assess vendor risks, review contracts, and ensure compliance with company policies. Clear communication and proactive follow-ups are key, as you may be managing multiple projects and stakeholders simultaneously. Building strong remote relationships helps streamline risk assessment processes and ensures effective risk mitigation strategies.

What is the difference between Third Party Risk Analyst Remote vs Vendor Risk Analyst?

AspectThird Party Risk Analyst RemoteVendor Risk Analyst
CredentialsCertifications like CRISC, CISA often preferredSimilar certifications, often including CRISC, CISA
Work EnvironmentRemote, primarily online collaborationRemote or on-site, depending on company policy
Industry UsageFinancial, healthcare, technology sectorsFinancial, retail, manufacturing sectors
Job FocusAssessing third-party risks and complianceEvaluating vendor security and operational risks

The main difference is that a Third Party Risk Analyst Remote focuses on assessing risks posed by third-party entities across various industries, often working remotely. A Vendor Risk Analyst typically concentrates on evaluating specific vendors' security and operational risks, which may involve more direct vendor interactions. Both roles require similar certifications and work environments, but their scope and focus differ slightly.

What are the most commonly searched types of Third Party Risk Analyst jobs in California? The most popular types of Third Party Risk Analyst jobs in California are:
What are popular job titles related to Third Party Risk Analyst Remote jobs in California? For Third Party Risk Analyst Remote jobs in California, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst Remote jobs in California look for? The top searched job categories for Third Party Risk Analyst Remote jobs in California are:
What cities in California are hiring for Third Party Risk Analyst Remote jobs? Cities in California with the most Third Party Risk Analyst Remote job openings:

Contractor

Posted 26 days ago


Job description

ABOUT APOGEE

Apogee Global RMS, LLC is a practitioner-led integrated enterprise risk management firm headquartered in San Jose, California. The firm operates on the Nexus of Risk thesis: that cyber, physical, and human capital risks are causally interconnected and must be governed as a unified discipline rather than treated as siloed verticals. Apogee serves North American small and mid-market enterprises and public sector clients across financial services, healthcare, professional services, technology, and education. The firm holds federal SDVOSB and California DVBE certifications.

ABOUT RRAG

The Rogue Risk Analysis Group is Apogee's risk intelligence and analyst research arm. RRAG produces subscription advisory products, sector briefings, and intelligence assessments grounded in the proprietary Nexus of Risk framework (12 domains across causal, consequence, and environmental tiers). The team's work supports client advisory engagements, executive briefings, and the firm's broader thought leadership program, including the Risk Apogee podcast and the RRAG webinar series.

POSITION SUMMARY

Apogee is engaging contract Risk Analysts at the journeyman level to expand RRAG's research and production capacity. The Risk Analyst is a proficient practitioner who can scope, research, and deliver written analytical products with limited supervision. The role reports to the Team Leader, RRAG, and collaborates with Apogee's Senior Risk Advisors and the firm's Cyber and Physical Risk practice.

This is a contract engagement structured for analysts who want substantive research work tied to a published product line, without the overhead of a full-time billet.

KEY RESPONSIBILITIES

  • Conduct primary and open-source intelligence research across one or more of the 12 Nexus of Risk domains: cyber, physical security, people, operational, financial, technology, safety, strategic, reputation, compliance and regulatory, supply chain, and geopolitical.
  • Produce written analytical products including flat-rate client advisories, sector briefings, alert notifications, and content for subscription-tier deliverables.
  • Apply structured analytic techniques to evaluate likelihood, impact, and intersection effects across risk domains, consistent with the Nexus of Risk methodology.
  • Use the Tacilent platform and adjacent intelligence tooling to support research workflows, evidence tracking, and product publication.
  • Maintain analytical rigor consistent with the Nexus of Risk taxonomy and Apogee editorial standards, including academic register in framework references and clear separation between framework content and illustrative examples.
  • Contribute research inputs to RRAG-supported assets, including the Risk Apogee podcast, the RRAG webinar series, and LinkedIn distribution content.
  • Participate in weekly editorial planning and product review with the RRAG team.

Requirements

REQUIRED QUALIFICATIONS

  • Three to seven years of professional experience in risk analysis, intelligence analysis, cybersecurity research, threat intelligence, geopolitical analysis, or a directly related research function.
  • Bachelor's degree in a relevant field, such as intelligence studies, security studies, international relations, computer science, risk management, criminal justice, public policy, or comparable.
  • Demonstrated portfolio of written analytical products. Candidates should be prepared to share two to three sanitized writing samples.
  • Working command of at least one Nexus domain, with analytical literacy across adjacent domains.
  • Proficiency with OSINT methods, source evaluation, and structured sourcing.
  • Strong written English. Ability to write to a defined editorial voice and to revise efficiently against feedback.
  • Capacity to operate independently on contract, manage deliverable timelines, and communicate proactively with the Team Leader, RRAG.

PREFERRED QUALIFICATIONS

  • Working knowledge of one or more risk management frameworks, such as NIST Cybersecurity Framework 2.0, NIST AI Risk Management Framework, ISO 31000, ISO 27001, COSO ERM, CMMC 2.0, or FAIR.
  • Prior experience in government, intelligence community, military, law enforcement, or regulated industry settings.
  • Relevant certifications, including but not limited to CISSP, CISM, CRISC, CFE, PSP, CPP, Security+, GIAC, or recognized intelligence analyst credentials.
  • Experience producing subscription-based intelligence or commercial advisory products.
  • Comfort with platform-based analytical workflows and AI-assisted research tooling.
  • Experience supporting executive or board-level audiences.

ENGAGEMENT TERMS

  • Contract role, structured as 1099 or W-2 contractor depending on jurisdiction and analyst preference.
  • Remote within the United States. Occasional travel for client engagements or firm offsites at Apogee expense.
  • Hourly or project-based compensation, market-competitive and commensurate with experience and domain depth.
  • Initial engagement scoped at six months, with renewal contingent on deliverable performance and ongoing product demand.
  • Apogee retains exclusive ownership of work product. Standard contractor confidentiality, non-disclosure, and intellectual property provisions apply.

Benefits

FIRM VALUES

Excellence.     Accountability.     Integrity.     Partnership.

HOW TO APPLY

Submit a current resume, two to three writing samples (sanitized as needed), and a one-paragraph statement of risk domain emphasis to information@apogeeglobalrms.com with the subject line "RRAG Risk Analyst Contract Application." Applications are reviewed on a rolling basis.